Effective June 4, 2026
Who we are
Growth House is the operating brand of Studio Sami LLC, a Florida limited liability company based in Davenport, Florida. This policy covers the Growth House marketing site and Studio OS, the platform that runs subscription builds. If you hired us for a one-time build that you host on your own infrastructure, your operational data lives with you, not us, and only the items in this policy that relate to our website and our business records apply.
What we collect
Account information you give us: name, email, business name, and the login details needed to access your portal. Client data you submit through your build: documents, prompts, answers, configurations, and the records your workflow processes. Outputs the workflow generates for you. Payment information, which is handled by Stripe; we never see or store full card numbers. Basic usage and security logs (such as sign-in events and errors) needed to operate the platform. We do not buy data about you, and we do not run advertising trackers on the portal.
How we use it
We use your information to build, run, and support your workflow, to authenticate you, to process payments, to send you service emails, and to keep the platform secure. We do not sell your data, we do not share it for advertising, and we do not use one client's data to do another client's work. Access to your data is limited to you and the operator running your build.
How AI processing works
Every AI step in your build runs on Anthropic's Claude models, accessed through Anthropic's commercial API, and only Anthropic. We do not send your data to OpenAI, Google, or any other AI provider for processing. Under Anthropic's commercial terms, the inputs and outputs we send are not used to train Anthropic's models, and Anthropic retains API traffic only briefly for abuse monitoring before discarding it. We do notbuild embeddings or a vector database from your documents, so there is no secondary AI copy of your data that outlives the original. You can review Anthropic's terms at anthropic.com/legal/commercial-terms.
Sub-processors
We rely on a small, named set of vendors to run the platform. Each is bound by its own terms and processes your data only to provide its service to us:
| Vendor | What it does | Where |
|---|---|---|
| Supabase | Database, file storage, and authentication | Amazon Web Services (United States) |
| Amazon Web Services | Underlying cloud infrastructure for the platform | United States |
| Anthropic | AI processing (Claude models) for the steps in your workflow | United States |
| Stripe | Payment processing for subscriptions and build fees | United States |
| Google (Gmail API) | Delivery of transactional and operator emails | United States |
| Cloudflare | DNS, content delivery, and network protection | Global edge network |
Where your data is stored and how it is protected
Your data is stored in Supabase, on Amazon Web Services, encrypted at rest with AES-256 and in transit over TLS. Each client's data sits in its own scope: every table and every private storage bucket has Row Level Security enabled with policies tied to your organization, enforced at the database layer so a query can only return rows that belong to you. Operator accounts that can reach client data are protected by app-based two-factor authentication; client sign-in uses one-time email magic links, so there is no reusable client password to steal. Supabase is SOC 2 Type II certified and independently audited; you can verify that at supabase.com/security.
How long we keep it
We keep your data for as long as your account is active. Inside the platform, your documents, prompts, and outputs live in your scope until you delete them or cancel. At the AI layer, Anthropic retains API traffic only briefly for abuse monitoring and then discards it. We do not maintain a separate long-term archive of your prompts and outputs outside your own scope. After cancellation we provide a one-time export within 30 days, after which we delete your data from the live platform.
Deleting your data
You can ask us to delete a specific document, a set of responses, or your entire account, and we will remove it from the live database and from file storage, not just hide it. Because there are no embeddings or vector copies, there is no hidden second version to chase down. Encrypted backups age out on their normal rotation rather than being individually edited; if you need a hard backup-purge commitment in writing, we can include that in a data processing addendum. Email your request to the address at the bottom of this page.
Your rights
You can ask us what data we hold about you, ask us to correct it, export it, or delete it. If you are covered by a privacy law such as the GDPR or a US state privacy act, we honor the access, correction, deletion, and portability rights it gives you. For business-sensitive or regulated data, we can sign a data processing addendum that names our sub-processors and commits us in writing to the no-training, deletion, and breach-notification terms described here.
Security incidents
If we ever discover a breach that affects your data, we will notify you without undue delay, tell you what we know, and tell you what we are doing about it. We will not sit on it.
Changes to this policy
If we change this policy in a way that materially affects how we handle your data, we will update the date above and let active clients know. Continued use of the platform after a change means you accept the updated policy.
Contact
Questions about this policy, or a request about your data, go to sami@thestudiosami.com. We read every one.